Microsoft Defender Experts observed phishing campaigns beginning in July 2026 that targeted organizations across multiple industries.
The phishing messages used familiar business scenarios to convince users to download and execute a file.
Microsoft observed lures involving:
Meeting invitations
PDF-related documents
Software-update notifications
Other business-themed content
But the downloaded program wasn't traditional malware.
It was a legitimate, digitally signed version of MSP360 Remote Monitoring and Management software disguised under deceptive filenames.
When the employee approved the installation—including the Windows User Account Control prompt—the RMM agent installed its services and established persistent remote access.
At that point, the attacker effectively had their own IT-management tool installed on the computer.
And they didn't stop there.
Attackers Installed a Second Remote-Access Tool
After establishing access through MSP360, Microsoft observed attackers using the RMM platform to execute PowerShell and silently install ConnectWise ScreenConnect.
That created a second remote-access channel.
Microsoft specifically noted that attackers were not exploiting a ScreenConnect vulnerability in this campaign.
Instead, they were using legitimate ScreenConnect software as another way to maintain control over the compromised computer.
Think of it like an attacker getting into a building and then installing a second door in case the first one gets locked.
Removing one remote-access tool might not remove the attacker.
Why Would Attackers Use Legitimate IT Software?Because it helps them blend in.
Remote monitoring and management software is commonly used by:
Managed service providers
Internal IT departments
Software vendors
Help desks
Equipment vendors
Remote technicians
These applications legitimately perform powerful administrative functions.
Depending on the product and permissions, an RMM platform may allow a technician to:
Remotely control a computer
Execute PowerShell
Run scripts
Install applications
Transfer files
Collect system information
Restart computers
Manage services
Troubleshoot systems
Those capabilities are incredibly useful for legitimate IT support.
They're also incredibly useful to an attacker.
This Creates a Difficult Security ProblemTraditional security thinking often focuses on identifying malicious programs.
But what happens when the attacker's software is legitimate?
MSP360 is legitimate.
ScreenConnect is legitimate.
PowerShell is legitimate.
Windows services are legitimate.
An attacker abusing these technologies may therefore appear, at least initially, similar to an IT administrator performing normal maintenance.
Microsoft's investigation demonstrates why modern endpoint security needs to evaluate behavior, not simply whether an application is known malware.
What Happened After Attackers Got Access?Once the remote-management infrastructure was established, Microsoft observed additional post-compromise activity.
Attackers used their remote access for information collection and attempted credential-access activity.
Microsoft Defender detected behaviors including:
Suspicious remote-management activity
Uncommon remote-access software
Suspicious services
Persistence mechanisms
Potential theft of browser passwords and sensitive information
The attackers were no longer trying to convince an employee to click something.
They were already inside the computer.
Why Small and Midsize Businesses Should Pay AttentionRMM software is particularly common in small and midsize businesses because many organizations outsource some or all of their IT operations.
That is not inherently a security problem.
Professional remote management allows an MSP to monitor computers, install updates, troubleshoot problems, deploy software, and respond quickly when something goes wrong.
The problem arises when businesses don't know which remote-management tools should be installed.
Over several years, a company may accumulate remote-access software from:
Its current IT provider
A previous IT company
Printer vendors
Accounting software vendors
Line-of-business software companies
Security vendors
Employees who installed remote-support applications themselves
You could potentially find several remote-access agents on the same computer.
And nobody remembers why they're there.
That creates unnecessary risk.
Your Business Should Have an Approved RMM ListEvery organization should be able to answer one simple question:
What software is authorized to remotely control our computers?
If the answer is unclear, that should become an IT-security priority.
Your IT provider should maintain an inventory of approved remote-management applications.
Anything outside that list should be investigated.
For example, if your organization normally uses one RMM platform and suddenly another remote-management agent appears on 15 computers, that should generate attention.
It might be legitimate.
Or it might be exactly the type of activity Microsoft recently observed.
What Businesses Should Do Now1. Inventory Remote-Access Software
Determine which remote-management applications exist across company computers and servers.
Common examples include:
ConnectWise ScreenConnect
MSP360
Splashtop
TeamViewer
AnyDesk
LogMeIn
BeyondTrust
Various MSP RMM agents
Vendor-specific remote-support software
Finding an application doesn't automatically mean it is malicious.
The important question is:
Who installed it, who controls it, and is it still required?
2. Remove Old RMM Agents
Changing IT providers should include removing the previous provider's remote-management software.
Old agents should not remain installed indefinitely.
The same principle applies to vendors.
If a software company needed temporary remote access six months ago, determine whether that software still needs to exist today.
Every unnecessary remote-access application creates another potential administrative pathway into your environment.
3. Restrict Software Installation
In Microsoft's observed attack, the user had to execute the disguised installer and approve elevation through Windows User Account Control.
That makes local administrator permissions important.
Employees should generally not have administrative privileges unless their job genuinely requires them.
Removing unnecessary local administrator rights can make it substantially harder for a phishing attack to become a full remote-access compromise.
4. Monitor for Unexpected RMM Software
Endpoint detection and response platforms should be configured to identify unusual remote-management activity.
Microsoft Defender for Endpoint, for example, includes detections for suspicious and uncommon remote-access software and behaviors associated with the campaign Microsoft investigated.
Businesses should not rely solely on traditional antivirus signatures.
The question isn't always:
"Is this application malicious?"
Sometimes the better question is:
"Should this application be running on this computer?"
5. Require MFA for Remote-Management Platforms
Your legitimate RMM platform is powerful.
Protect it accordingly.
Technicians should use individual accounts protected with multifactor authentication whenever the platform supports it.
Avoid shared technician accounts whenever possible.
That provides both stronger authentication and better auditing.
If suspicious activity occurs, you want to know exactly which account initiated the remote session.
6. Train Employees About Fake Software Updates
Employees should be suspicious of unexpected emails asking them to install:
Software updates
Meeting applications
Remote-support software
PDF readers
Browser updates
Security applications
Software updates should ideally be managed centrally by IT rather than installed from links employees receive through email.
A simple rule can prevent many attacks:
If an email tells you to install software, contact IT first.
7. Don't Assume Removing One Tool Ends the Incident
This attack demonstrates another important incident-response lesson.
If unauthorized RMM software is discovered, simply uninstalling it may not be enough.
Microsoft observed attackers installing multiple remote-access mechanisms.
An investigation should determine:
How the software was installed
When it appeared
Which user executed it
What commands were run
Whether another RMM agent was installed
Whether credentials were accessed
Whether additional computers were contacted
Whether persistence mechanisms were created
Whether accounts need passwords or tokens reset
Finding unauthorized remote-access software should be treated as a potential security incident—not simply unwanted software.
The Bigger Cybersecurity LessonFor years, businesses were taught that cybersecurity meant preventing malicious programs from entering the network.
That model is becoming outdated.
Modern attackers increasingly abuse legitimate technology.
Remote-management applications.
PowerShell.
Cloud services.
Microsoft 365.
OAuth applications.
Remote desktop tools.
Attackers don't necessarily need to create sophisticated malware when trusted administrative tools already provide the capabilities they need.
That's why modern cybersecurity increasingly depends on understanding what is normal for your environment.
If your company uses one approved RMM platform, seeing another one suddenly appear should be unusual.
If employees normally receive software through centralized IT management, someone manually downloading a remote-support installer should be unusual.
Security tools—and the people monitoring them—need enough visibility to recognize those differences.
How MicroAdvantage Can HelpAt MicroAdvantage, remote management is an important part of how we support and protect our clients—but remote access also needs to be carefully controlled.
We help businesses understand exactly who can access their systems, what tools provide that access, and how those tools are protected.
A MicroAdvantage IT and cybersecurity review can include:
RMM and remote-access software auditing
Removal of unauthorized or outdated remote tools
Microsoft Defender for Endpoint
Endpoint detection and response
Windows patch management
Local administrator reviews
Microsoft 365 security
Multifactor authentication
Conditional Access
Firewall and network security
Email and phishing protection
Backup and disaster recovery
User security awareness
Cybercriminals are increasingly trying to make their activity look like normal IT administration.
That means businesses need more than antivirus.
They need visibility.
If you're not sure what software can remotely access your company's computers—or who controls it—MicroAdvantage can help you find out and make sure that access is properly secured.
Sources
Microsoft Security Blog — “Phishing Abuses RMM Tools for Persistent Access,” published September 29, 2026. Microsoft's investigation provides the primary technical details about the MSP360 phishing campaign, ScreenConnect deployment, persistence, credential-access activity, and recommended defenses.
CISA — Cybersecurity Alerts & Advisories. CISA continues to highlight active exploitation and the importance of rapidly addressing vulnerabilities and threats affecting internet-facing and administrative infrastructure.
MicroAdvantage Takeaway
Know what can remotely access your computers. Know who controls it. Secure it like an administrator account.